<?php
session_start();
include '../class/connect.inc.php';
switch($_POST['action']){
case 'login':	
	$bool=false;
	if($_POST['username']&&$_POST['pass']){
		$sql='select id,user,authority,nick_name from user where user="'.$_POST['username'].'"'.' and password="'.md5($_POST['pass']).'"';
		$result=$mysqli->query($sql);
		if($row=$result->fetch_assoc()){
			$_SESSION['id']=$row['id'];
			$_SESSION['authority']=$row['authority'];
			$_SESSION['nick_name']=$row['nick_name'];
			$_SESSION['username']=$row['user'];
			$bool=true;
		}
	}
	echo $bool;
	break;
case 'logout':
	$_SESSION=array();
	$_COOKIE[session_name()]='';
	echo true;
	break;
case 'islogin':
	if($_SESSION['id']){
		$nick=$_SESSION['nick_name'];
		$status=true;
		$name=$nick?$nick:$_SESSION['user'];
	}else{
		$status=false;
		$name=null;
	}
	echo '{"name":"'.$name.'","islogin":"'.$status.'"}';
	break;
case 'check_coder':
	echo $_COOKIE['position']=='coder'?true:false;
	break;
case 'get_position':
	$out=$_COOKIE['position']?$_COOKIE['position']:'home';
	include '../'.$out.'.html';
	break;
case 'get_active_position':
	$out=$_COOKIE['position']?$_COOKIE['position']:'home';
	echo $out;
	break;
case 'set_position':
	$p=$_POST['current_position']?$_POST['current_position']:'home';
	setCookie('position',$p,0);
	break;
}
